Details
-
Bug
-
Status: Open
-
Major
-
Resolution: Unresolved
-
XSS Protection API 2.2.6
-
None
-
None
Description
while
xssApi.encodeForCSSString should righteously encode "JavaScrIpt some text>" into "JavaScrIpt some text
3e"it should leave ".foo > .bar { some rule }" alone as changing here the '>' character will break the CSS